AVG:
扫描:miss;
双击:样本运行后释放衍生物,添加启动项后自删除,好像还注入explorer.exe,但IDP依旧kill。
"";"IDP.ARES.Generic, C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-18611771\KdjSaS011arhaaaa.exe";"Deleted, Moved to Virus Vault";"File or Directory";"2015/12/8, 18:40:20"
"";", C:\Windows\explorer.exe";"Object was blocked";"Process";"2015/12/8, 18:40:20"
"";", C:\USERS\KILLER.KILLER-PC\DESKTOP\197FJR1DKQWKJDQWKJBDQKBKDJBQKWJDBQK82701919IUDHQIU.EXE";"Object was blocked";"Process";"2015/12/8, 18:40:20"
"";", HKEY_USERS\S-1-5-21-1910074467-3606790842-1030588025-1003\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\KDJSAS011ARHAAA";"Deleted, Moved to Virus Vault";"Registry value";"2015/12/8, 18:40:20"
"";", HKEY_USERS\S-1-5-21-1910074467-3606790842-1030588025-1003\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE\\KDJSAS011ARHAAA";"Deleted, Moved to Virus Vault";"Registry value";"2015/12/8, 18:40:20"
|